Security

Security at SuiteCue

We handle door access, rent, and client phone numbers. Here is how we protect them.

Encryption

Traffic to SuiteCue is encrypted in transit. Sensitive values we store are encrypted at rest with AES-256-GCM. That covers door-system credentials, building-wide fallback codes, PINs, and tax IDs.

Each organization has its own data key, and those keys are wrapped by a master key that carries a version number. Every stored value records the key version it was encrypted under, so we can rotate keys without losing access to older data.

PINs, QR codes, and pass links

  • PINs, QR links, and pass links are never written to our logs. Logging redacts them, and stored message records keep a redacted copy of the text.
  • Pass links are 256-bit random tokens. We store only a hash of each token.
  • A pass link works only inside the appointment window set by the building, and it stops working after the window ends.
  • Analytics text is masked, session replay is off, and door pass pages are excluded from analytics.
  • When an appointment is cancelled, marked a no-show, or a pro is offboarded, the pass is revoked.

Payments

Card and bank details are entered into Stripe’s own fields, so they go to Stripe and never touch SuiteCue servers. This keeps us in the simplest PCI scope, SAQ-A. Pros are paid through Stripe Connect Express, directly from Stripe to the pro’s account. SuiteCue does not hold pro funds.

Webhooks and integrations

Every webhook we receive from Stripe, Seam, and Telnyx has its signature verified before we act on it. We store each event, so any event can be replayed if a handler fails.

Access control and audit log

  • Every request is checked against the signed-in person’s role and, for managers, the locations they are assigned to. Data queries are scoped to one organization at a time.
  • Sign-in uses email links and passkeys.
  • Booking, one-time code, and sign-in endpoints are rate limited by IP address and by phone or email.
  • Every input to a form or API is validated on the server before it is used.
  • An audit log records access setup, pass issue and revoke, offboarding, fee and policy changes, data exports, message template edits, and actions by SuiteCue staff.

Before a client is texted, we record the consent text they saw, when they agreed, and where. Replies of STOP are honored right away. See the SMS terms.

Report a vulnerability

If you believe you have found a security problem in SuiteCue, email security@suitecue.com. Please include what you found, the steps to reproduce it, and how to reach you.

While you investigate, we ask that you:

  • Use only your own accounts and test data, and do not access or change anyone else’s data.
  • Do not disrupt the service or run automated attacks that degrade it.
  • Give us a reasonable chance to fix the problem before you share it publicly.

We will acknowledge your report, keep you updated, and not take legal action against good-faith research that follows these guidelines.